3D Gaussian Splat Vulnerabilities
By: Matthew Hull , Haoyang Yang , Pratham Mehta and more
Potential Business Impact:
Hides secret messages in 3D pictures.
With 3D Gaussian Splatting (3DGS) being increasingly used in safety-critical applications, how can an adversary manipulate the scene to cause harm? We introduce CLOAK, the first attack that leverages view-dependent Gaussian appearances - colors and textures that change with viewing angle - to embed adversarial content visible only from specific viewpoints. We further demonstrate DAGGER, a targeted adversarial attack directly perturbing 3D Gaussians without access to underlying training data, deceiving multi-stage object detectors e.g., Faster R-CNN, through established methods such as projected gradient descent. These attacks highlight underexplored vulnerabilities in 3DGS, introducing a new potential threat to robotic learning for autonomous navigation and other safety-critical 3DGS applications.
Similar Papers
ComplicitSplat: Downstream Models are Vulnerable to Blackbox Attacks by 3D Gaussian Splat Camouflages
CV and Pattern Recognition
Hides things in pictures only seen from certain angles.
GaussTrap: Stealthy Poisoning Attacks on 3D Gaussian Splatting for Targeted Scene Confusion
CV and Pattern Recognition
Makes 3D scenes unsafe for self-driving cars.
RemedyGS: Defend 3D Gaussian Splatting against Computation Cost Attacks
CV and Pattern Recognition
Protects 3D pictures from being broken by hackers.